Restructuring GitHub's bug bounty program
soheilpro
31 points
14 comments
July 23, 2026
Related Discussions
Found 5 related stories in 646.8ms across 14,736 title embeddings via pgvector HNSW
- Node.js Security Bug Bounty Program Paused 0xedb · 14 pts · April 02, 2026 · 65% similar
- We are retiring our bug bounty program tjek · 348 pts · May 15, 2026 · 58% similar
- GitHub is sinking herbertl · 220 pts · May 10, 2026 · 54% similar
- GitHub and the crime against software pplanu · 208 pts · June 01, 2026 · 53% similar
- GPT‑5.5 Bio Bug Bounty Murfalo · 142 pts · April 25, 2026 · 53% similar
Discussion Highlights (8 comments)
dinkelberg
So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
Klaster_1
Dupe: https://news.ycombinator.com/item?id=49010107
saagarjha
I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.
applfanboysbgon
I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...
fragmede
That's a weird way to do it. Yes, there's a wave of low quality reports, but a vuln is a vuln. The filter mechanism shouldn't affect the payout amount. What if we just give people who are white a higher payout because they are white? That seems fair, right?
wxw
> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. > VIP program bounty table: Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+ > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range. > Our new public program bounty table: Severity Payout -------- ------- Low $250 Medium $2,000 High $5,000 Critical $10,000 > To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.
Schnitz
It is much harder to refute bullshit than to make up bullshit. As harsh or unfair as it might seem, this makes sense.
darkamaul
I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame. Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.